PT-2015-1472 · Adobe+3 · Flash Player+3

Published

2015-06-10

·

Updated

2025-11-17

·

CVE-2015-5119

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 11.x through 11.2.202.468 Adobe Flash Player versions 13.x through 13.0.0.296 Adobe Flash Player versions 14.x through 18.0.0.194
Description The issue is caused by a use-after-free vulnerability in the ByteArray class in the ActionScript 3 implementation. This vulnerability can be exploited by remote attackers to execute arbitrary code or cause a denial of service via crafted Flash content that overrides a valueOf function. The vulnerability has been exploited in the wild in July 2015.
Recommendations For Adobe Flash Player versions 11.x through 11.2.202.468, update to a version that contains a fix for this issue. For Adobe Flash Player versions 13.x through 13.0.0.296, update to a version that contains a fix for this issue. For Adobe Flash Player versions 14.x through 18.0.0.194, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to crafted Flash content that overrides the valueOf function in the ByteArray class until a patch is available.

Exploit

Fix

DoS

RCE

Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1526
ALT-PU-2015-1596
ALT-PU-2015-1674
BDU:2015-10660
BDU:2015-10661
CVE-2015-5119
MGASA-2015-0273
OPENSUSE-SU-2015_1207-1
RHSA-2015:1214
RHSA-2015_1214
SUSE-SU-2015:1211-1
SUSE-SU-2015_1211-1
SUSE-SU-2015_1214-1

Affected Products

Alt Linux
Flash Player
Red Hat
Suse